nerdexam
Cisco

300-720 · Question #142

An organization has strict rules for meeting specific criteria to approve certificate authorities. A Cisco ESA administrator within the organization is receiving complaints about failed inbound…

The correct answer is D. The certificate chain is broken. TLS certificate errors for inbound emails, especially with strict CA approval rules, are commonly caused by a broken certificate chain.

Email Authentication and Encryption

Question

An organization has strict rules for meeting specific criteria to approve certificate authorities. A Cisco ESA administrator within the organization is receiving complaints about failed inbound emails from a domain. The administrator is also seeing TLS certificate errors. What is the reason for this issue?

Options

  • AFirewall inspection is preventing transmission of certificate data.
  • BThe certificate authority is not on the system list.
  • CThe TLSv1.0 protocol is not supported.
  • DThe certificate chain is broken.

How the community answered

(50 responses)
  • A
    4% (2)
  • B
    18% (9)
  • C
    8% (4)
  • D
    70% (35)

Why each option

TLS certificate errors for inbound emails, especially with strict CA approval rules, are commonly caused by a broken certificate chain.

AFirewall inspection is preventing transmission of certificate data.

Firewall inspection preventing transmission would result in general connection failures, not specific 'TLS certificate errors' indicating a problem with the certificate's validity.

BThe certificate authority is not on the system list.
CThe TLSv1.0 protocol is not supported.
DThe certificate chain is broken.Correct

A broken certificate chain is the most likely reason for TLS certificate errors when an organization has strict CA approval rules and experiences failed inbound emails. This means the Cisco ESA cannot establish a complete and trusted path from the presented server certificate back to a trusted root certificate authority, leading to validation failure and connection termination.

Concept tested: Cisco ESA TLS certificate chain validation

Source: https://www.cisco.com/c/en/us/td/docs/security/esa/esa12-0/user_guide/b_ESA_Admin_Guide_12_0/b_ESA_Admin_Guide_12_0_chapter_01011.html

Topics

#TLS#Certificate Chain#Email Encryption#Cisco ESA

Community Discussion

No community discussion yet for this question.

Full 300-720 Practice